Syndikeeper · Controller: Halcyon Labs Ltd · Version 0.0.2 (beta) · Last updated 3 October 2026
Beta version (v0.0.2) for testers. This notice describes how Syndikeeper handles your data today, during the beta. It will be updated before public launch.
At a glance. This summary is for convenience only; the full sections below govern. We hold no funds and take no payments. Syndikeeper is free and there is no billing data of any kind. Analytics are off until you turn them on. No analytics data is collected or sent before you opt in. Deletion is real but not total. Your name and contact details are deleted; your entries stay in other members’ records as “Former member”. 18+ only, and records are visible to your own syndicate members by design.
Who we are. Syndikeeper is operated by Halcyon Labs Ltd, trading as Syndikeeper, an Irish company (company number 823886, registered at Venture Hub, 136 Capel Street, Dublin, D01 T2C9, Ireland). We're the data controller for your personal data. Contact for anything privacy-related: privacy@syndikeeper.com. For general support: support@syndikeeper.com.
What Syndikeeper is (and isn't). Syndikeeper is a private record-keeping and administration tool for betting and lottery syndicates. We don't hold funds, place bets, or pay out winnings.
Who can use it. Syndikeeper is for people aged 18 or over. We ask for your date of birth and require you to confirm you're 18 or over; we don't accept accounts from anyone under 18. Your date of birth can't be changed in the app, because it's how we check age. If it's wrong, email privacy@syndikeeper.com from your account's email address and we'll correct it; we don't ask for ID documents. If the correct date shows you're under 18, we'll close your account and erase your data.
What it costs. Syndikeeper is currently free. We don't take payments, so we hold no billing or card data of any kind. If we introduce paid features we'll update this notice first.
1 · What we collect
- Account details — name, email, date of birth, country and language, and how you sign in (including two-factor sign-in, if you turn it on).
- Syndicate records — the bets, contributions, winnings and membership details you and your syndicate's admins record, including join requests and saved lottery numbers. Some of this is entered about you by your syndicate admin, and history files an admin imports can name people who haven't joined yet.
- Slip images and import files — photos of betting slips and lottery tickets, and files you import (such as PDFs or spreadsheets). If you choose to, we read bet details from photos and PDFs automatically (see "Automated processing" below). We remove location and camera data from photos when you upload them.
- Usage analytics and (web only) session replays — only if you say yes to the in-app prompt. Off by default. We also keep a record of your answer and when you gave it.
- Technical basics — device and app version, a push notification token for each device you use, simple usage counters, error reports so we can fix crashes, and standard server logs (including your IP address) kept briefly by our hosting providers for security and troubleshooting.
- Sign-in security log — a record of sign-ins and security events on your account (such as time, IP address and device), to protect your account.
- Reports — if you report a member or a bet, we store who reported, who was reported, the syndicate, a copy of the reported content, your reason, any note you add (up to 500 characters) and the outcome. We don't tell the member who reported them.
- Blocks — who you have blocked, and when. The person you block isn't told.
- Your acceptances — which versions of our Terms and this notice you accepted, and when.
2 · Why, and on what legal basis
| PURPOSE | BASIS |
|---|---|
| Providing the service — accounts, syndicate records, ledgers, exports | Contract |
| Age-gating (18+ service) | Legitimate interests (preventing underage use of a gambling-adjacent service) |
| Product analytics and session replay | Consent (opt-in, withdrawable in Profile → Privacy & security → Your data) |
| Error monitoring and security/server logs | Legitimate interests (keeping the service working and secure) |
| Rate-limiting and abuse prevention | Legitimate interests (protecting the service and its users) |
| Blocking an email from new accounts, at your request on deletion | Legitimate interests (a protective measure you ask for) |
| Reading slip and ticket photos and PDFs automatically (Gemini) | Consent (asked once, before first use; you can enter details by hand instead) |
| Sign-in security log | Legitimate interests (protecting your account) |
| Handling reports, and removing content or accounts that break our Terms | Legitimate interests (keeping users and the service safe) |
| Blocking members | Contract (a feature you choose to use) |
| Recording which versions of our Terms and this notice you accepted | Legitimate interests (showing what you agreed to) |
Automated processing. When you upload a slip or ticket photo or a PDF and choose automatic reading (we ask you once, first), we use Google's Gemini vision model to read the bet details from it automatically. You (or your admin) can review and correct the extracted details — no decision with legal or significant effect is made solely by automation. We use Gemini on Google's paid service terms, under which Google doesn't use your files to train its models. We send only the photo or PDF you upload, not your name or email, though the file itself may show information such as names on a syndicate summary.
3 · Cookies & device storage
On the web, before you opt in to analytics, no analytics code runs and no analytics cookie or identifier is stored on your device. We store only what the app needs to work: your sign-in session, your language, theme and similar preferences, and a count of failed sign-in attempts (to protect against password guessing). Analytics storage is set only after you opt in. The mobile app stores your sign-in, your settings and a cached copy of your home screen; its analytics component also creates a random identifier on your device when the app starts, but sends nothing unless you opt in. We don't use advertising cookies of any kind.
One thing that happens without storing anything: our error-monitoring provider (Sentry, EU-hosted) receives a request from your browser when a page loads, which means it sees your IP address. It sets no cookie and stores nothing on your device. This runs on legitimate interests, so it doesn't wait for consent.
4 · Who we share it with (processors)
| PROVIDER | WHAT THEY DO | WHERE |
|---|---|---|
| Supabase | Database, file storage and sign-in | Ireland |
| Cloudflare R2 | A second copy of uploaded images and files | EU |
| Railway | Application hosting and server logs | Netherlands |
| Vercel | Web hosting and access logs | Ireland |
| PostHog | Product analytics and web session replay — only with your consent | EU |
| Sentry | Error monitoring | Germany |
| Upstash | Short-lived rate-limiting counters keyed to account or syndicate IDs, or your IP address, expiring within about an hour | Belgium |
| Reading bet details from slip photos and PDFs (Gemini) — only with your consent | United States and other countries | |
| Expo | App builds, and delivering push notifications to your device (which can include member names, syndicate names, amounts and bet descriptions) | United States |
| Resend | Sending sign-in and account emails | Ireland |
| GitHub | Encrypted nightly database backups, kept 30 days | United States |
| Apple and Google | Final delivery of push notifications to your device | United States and other countries |
| Google Workspace | Our support and privacy mailboxes, if you email us | Global |
| ngrok | A secure connection some beta test builds use to reach our servers | Global |
Each works only on our instructions, under data-protection terms in its contract with us (for most providers, their standard terms).
Almost everything that stores your data sits in the EU — your account, your syndicate records and your images. Our encrypted nightly database backups (kept 30 days) are currently held by GitHub in the United States; we plan to move them to EU storage. A few other providers handle data outside the EU, without storing it long-term: Google reads the photos and PDFs you choose to have read automatically (see "Automated processing" above), and Expo delivers push notifications, which means it handles your device's push token and the text of the message (passed to Apple or Google for delivery). Some of our EU-hosted providers are companies based outside the EU (for example, our database contract is with Supabase Pte. Ltd in Singapore), so their support and operations staff may access data from outside the EU, and some keep their own service logs outside the EU. Wherever data leaves the EU, it's protected by the EU–US Data Privacy Framework where the provider is certified, or by the European Commission's Standard Contractual Clauses.
We don't sell your data and don't share it for advertising.
Signing in with Google. On the web, you can choose to sign in with Google. Google confirms who you are and shares your email address (and your name, if you allow it) with us, under Google's own privacy policy.
Other syndicate members. By design, members of your syndicate see the records you share with them — your display name, bets, contributions and winnings within that syndicate. When you ask to join a syndicate, its admins see your request before you're a member. That's the product. People outside your syndicates see nothing.
5 · How long we keep it
- Account and profile data: while your account exists.
- Slip images and the raw text read from them: the raw reading is deleted 90 days after the bet is settled; the bet details themselves are kept. Slip and ticket images, and files you import, are kept until your account is deleted or the syndicate's records are deleted. If we start deleting images automatically after a set period, we'll update this notice first.
- Syndicate records: while the syndicate is active. If a syndicate is retired, it becomes read-only 18 months later and its records are deleted 24 months after it was retired. If a syndicate goes quiet, it's flagged as dormant after 12 months without activity, becomes read-only 18 months after that, and is deleted 24 months after it went dormant (about 3 years after the last activity). Current members are notified in the app at each stage.
- Notifications: 90 days.
- Analytics: 12 months, and only while your consent stands.
- Server logs: short rolling windows set by our hosting providers.
- Sign-in security log: 90 days.
- Reports: 12 months after we resolve them; open reports are kept until resolved.
- Blocks: until you unblock the person or your account is deleted.
- Emails to support or privacy: 3 years after the matter is resolved.
- Database backups: 30 days (see below). The second copy of your images (Cloudflare R2) follows the same rules as the images themselves.
- Full schedule criteria: available on request at privacy@syndikeeper.com.
6 · Deleting your account, and what it really means
You can delete your account any time in the app: Profile (the “You” tab on mobile) → Privacy & security → Your data → Delete my account. If you can't sign in, email privacy@syndikeeper.com from your account's email address. There's a 14-day grace period in case you change your mind — during it your account is frozen, and you can cancel by signing back in and choosing Cancel deletion. After that:
- Your login, email, name, date of birth, country, photos, push tokens and the slip images you uploaded are permanently deleted.
- Your past bets and contributions that form part of other members' shared records are de-identified — your name and contact details are removed and the entries show as “Former member”. An internal reference remains so the syndicate's records stay consistent, so this is de-identification rather than full anonymisation. Text you typed into shared records (such as bet descriptions) stays as written. We keep these records because other members are entitled to their own accurate syndicate history and records may be needed if a dispute arises.
- We also keep, with the “Former member” record, which versions of our Terms and this notice you accepted and, if you consented to analytics, that you did and when, so we can show what you agreed to. Reports made by or about you are kept for their normal period (see above).
- Backup copies are encrypted and expire after 30 days. Until then they're locked and unused, and if we ever restore from a backup, re-running deletion is a required step before the data is used.
- Deletion is irreversible and your history can't be restored, even with a new account on the same email.
- Optionally, you can ask us to block your email from opening a new account for 6 months, 1 year, 5 years, or until you ask us to remove it — we keep only a scrambled fingerprint of the address, nothing else.
- If we close your account under our Terms of Service, you're signed out and can't sign back in. Your data isn't deleted automatically: you can ask us to delete it at privacy@syndikeeper.com, and we'll then follow the same process as above.
7 · Your rights
Access a copy of your data, download it in a portable format, correct it, delete it, restrict or object to processing, and withdraw any consent — all free, normally answered within one month. Contact privacy@syndikeeper.com.
Your download (Profile → Privacy & security → Your data → Export my data) is a JSON file containing your profile, bets, contributions, winnings, memberships, history, notifications, the Terms you accepted and your devices. Slip images you uploaded are included as download links that expire 24 hours after the export is generated, so save them promptly. It doesn't include reports or blocks. You won't receive other members' personal data in your export, just as they don't receive yours.
If you're not happy with how we handle your data or a request, you can complain to your regulator:
| WHERE YOU LIVE | REGULATOR |
|---|---|
| Ireland / EU | Data Protection Commission — dataprotection.ie (our lead regulator) |
| UK | Information Commissioner's Office — ico.org.uk (applies from UK availability — not at launch; UK representative appointed then) |
| Australia | Office of the Australian Information Commissioner — oaic.gov.au |
| New Zealand | Office of the Privacy Commissioner — privacy.org.nz |
UK users (from UK availability): the UK GDPR and Data Protection Act 2018 apply to our handling of your data. Australian users: we handle your information consistently with the Australian Privacy Principles. NZ users: we handle your information consistently with the Privacy Act 2020's information privacy principles.
8 · Breaches
If a breach ever puts your data at meaningful risk, we'll tell the relevant regulator within the required deadline and tell you directly, in plain language, without undue delay.
9 · Changes
We'll post changes here. For material changes, we'll ask you to accept the updated notice in the app. This notice was last updated on 3 October 2026.
Languages: this notice is written in English. We may provide translations for convenience. If a translation differs from the English version, the English version applies, to the extent the law allows.